Threat reportPhishingTL-2026-2998

Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue ScreenConnect RMMs

highACTIVE

Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue (TL-2026-2998) is a high-severity phishing campaign, first published 2026-10-07. It has no confirmed attribution, affects Microsoft Power BI (public report sharing abused as lure host), maps to 11 MITRE ATT&CK techniques (T1053.005, T1059.001, T1059.003), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2998

Threat ID
TL-2026-2998
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
24

Malware and tooling in Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue

Malware and tooling: ConnectWise ScreenConnect, HideUL, ScreenConnect

How Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue works

Huntress observed phishing emails linking to fake reference documents on public Microsoft Power BI pages. A 'Download Reference' button opens attacker-controlled sites that fingerprint the host and then auto-download a rogue ScreenConnect client; a second ScreenConnect instance, a defense-evasion tool (HideUL_x64.exe) and a 2-minute scheduled task provide redundant persistence.

Huntress SOC analysts observed a phishing campaign starting around 2026-09-10 that abuses Microsoft Power BI to host its lure. Victims receive an email (delivered to Outlook) containing a link to a public Power BI report on the legitimate app.powerbi.com domain. The report presents a fake reference document with a 'Download Reference' button, so the lure inherits the reputation of a trusted Microsoft service and slips past controls that trust the domain.

Clicking the button opens a new browser tab on an attacker-controlled site (observed: dailylifeproject.site, burnsworth.site, essaywritingservice.site, openpediatrics.site, each serving /S/ or /S/main.html). JavaScript on the page fingerprints the visitor: operating system, browser and version, mobile vs desktop, user agent, screen size, iframe context, cloud-provider cookies, public IP, geolocation, ISP, approximate coordinates, device type, UTC timestamp and automation indicators. Only Windows desktop visitors on non-Microsoft/known ISPs proceed; failed checks are redirected to check.vykyn.click/E/. Visitor telemetry is reported to a hardcoded Telegram bot credential that was reused across campaign domains. After a delay the page automatically downloads ScreenConnect.ClientSetup.exe from an attacker-controlled ScreenConnect cloud instance (hamham27.screenconnect.com, with guest-access parameters t=ILEAYEASAN, PERFECTO or PAPASUPE).

The first rogue client (instance ID 2b302081e9e777d0, relay instance-g01s1n-relay.screenconnect.com) executes LyN03DvVjUKPrun.cmd, which installs a second ScreenConnect client (instance ID 43773b3da4ccb17b) pointing at onthegotree.site, downloaded as ScreenConnect.ClientSetup.msi. The actor then runs the defense-evasion tool HideUL_x64.exe, described by Huntress as designed to hide the attacker's activity from the user and security software, and creates the scheduled task SCAutoRepairEvery2Min, which runs SCAutoFix.ps1 every two minutes. Multiple RMM clients mean that if one is removed another remains. Huntress's retrospective hunt found 22 additional impacted endpoints beyond the initial handful. No threat actor, sector or region attribution is given and no CVE is involved. The second-instance SHA256 (f048400c...) also appears in separate Huntress browser-in-the-browser (BiTB) Adobe-lure incidents from August 2026, indicating shared tooling or operators across rogue-ScreenConnect campaigns.

MITRE ATT&CK techniques used in TL-2026-2998

Persistence

T1053.005 Scheduled Task

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.001 Malicious Link; T1204.002 Malicious File

Command and Control

T1219.002 Remote Desktop Software

Defense Evasion

T1480 Execution Guardrails; T1497.001 System Checks; T1564 Hide Artifacts

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains

Affected products and versions in Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue

  • Microsoft — Power BI (public report sharing abused as lure host)
  • ConnectWise — ScreenConnect (legitimate RMM abused via attacker-controlled instances)
  • Microsoft — Windows (desktop endpoints, the only OS served the payload)

Remediation for Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue

Immediate actions

  • Block and hunt for the listed staging domains, hamham27.screenconnect.com, instance-g01s1n-relay.screenconnect.com and onthegotree.site
  • Isolate endpoints with unapproved ScreenConnect clients, then remove all rogue instances (both clients), the SCAutoRepairEvery2Min task and SCAutoFix.ps1
  • Hunt for HideUL_x64.exe and LyN03DvVjUKPrun.cmd

Workarounds

  • Monitor for new or unexpected ScreenConnect installations and connections to unapproved ScreenConnect instances
  • Monitor creation of scheduled tasks or scripts associated with remote access tools

Longer-term hardening

  • Restrict remote management software to approved instances (allowlist ScreenConnect instance IDs / relay hosts)
  • Review phishing protections and user-reporting workflows for links hosted on trusted cloud services (Power BI) that lead to downloads
  • Alert on endpoints with multiple RMM clients installed

Timeline of Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue

  • Related Huntress-analyzed rogue ScreenConnect phishing (Bank of America 'Account Guard' lure) reported by Help Net Security, showing the broader rogue-ScreenConnect trend
  • Huntress SOC investigates first browser-in-the-browser Adobe-lure incident delivering two rogue ScreenConnect clients and HideCursor/HideUL (shares SHA256 f048400c... with this campaign)
  • Second BiTB Adobe-lure incident with redundant ScreenConnect instances; Defender flagged patch.msi but did not prevent execution
  • Per incident, first ScreenConnect client runs LyN03DvVjUKPrun.cmd, installs second client, launches HideUL_x64.exe and creates SCAutoRepairEvery2Min running SCAutoFix.ps1 every 2 minutes
  • Huntress first observes the Power BI phishing campaign hitting a handful of endpoints, with Power BI lure, fingerprinting landing pages and rogue ScreenConnect installs
  • Huntress publishes the report; retrospective threat hunt identified 22 additional impacted endpoints

Sources cited for Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue

Detection coverage for TL-2026-2998

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2998 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats